Not directly in Observium, but you can easily pre-filter them in the syslog-ng (or rsyslog) config, by simply not passing in, or blackholing, anything coming in at that level.

 

For syslog-ng, the relevant section of documentation is at syslog-ng Open Source Edition 3.16 - Administration Guide.  It should be fairly straightforward to follow.

The equivalent rsyslog documentation is at RSyslog Documentation - rsyslog and… well, good luck understanding that, I certainly don’t.

 

-Adam

 

Adam Thompson

Consultant, Infrastructure Services

MERLIN

100 - 135 Innovation Drive

Winnipeg, MB R3T 6A8

(204) 977-6824 or 1-800-430-6404 (MB only)

https://www.merlin.mb.ca

Chat with me on Teams

 

From: Lars Joergensen via observium <observium@lists.observium.org>
Sent: January 13, 2023 12:49 PM
To: Observium <observium@observium.org>
Cc: Lars Joergensen <DKLARJ@chr-hansen.com>
Subject: [Observium] Ignore priority 7 syslog

 

Hi

 

Some unfortunate soul enabled BGP debugging on a device and then forgot all about it.

 

I’m now trying to delete 76 million records from the syslog database..

 

Is there a way to ignore syslog messages with priority 7 in the syslog import in Observium? It’ll probably happen again someday.

 

 

Lars


Disclaimer: This e-mail, including any attachments, is for the intended recipient only. If you have received this e-mail by mistake please notify the sender immediately by return e-mail and delete this e-mail and any attachments, without opening the attachments, from your system. Access, disclosure, copying, distribution or reliance on any part of this e-mail by anyone else is prohibited. This e-mail is confidential and may be legally privileged. Chr. Hansen does not represent and/or warrant that the information sent and/or received by or with this e-mail is correct and does not accept any liability for damages related thereto. https://www.chr-hansen.com/en/legal-notice